Security Operations Engineer [Remote]
Yellow Card
- Remote job
Who We Are
[Yellow Card]( is the largest licensed Stablecoin-based infrastructure provider operating across over 60 countries. From Stablecoin payment infrastructure to fiat settlement rails, wallet services, and custom local Stablecoin issuance, Yellow Card provides the complete infrastructure businesses need to manage Stablecoins, payments, and operations across 50 emerging markets.
Yellow Card operates with a substantial global team spanning 24 countries. This workforce is characterized by its linguistic diversity, with collective speaking of over 25 languages, underscoring the company’s extensive international reach.
The Security Operations Engineer is the operational backbone of the Security Operations Centre (SOC). It is a fully remote, hands-on, technical role that owns three tightly integrated domains: security alert design, triaging, and automated response; cloud security posture management across EKS and AWS environments; and posture tracking and reporting.
Reporting to the Associate Director, Product & Infrastructure Security, the engineer works alongside a mature Application Security team and collaborates closely with DevOps, Engineering, and Security GRC functions. The role sits within the First Line of Defense and is expected to progressively drive down manual effort through detection-as-code and SOAR automation.
This is not a perimeter-security or scan-and-report role. The right candidate must be comfortable writing detection logic, triaging cloud misconfigurations at the infrastructure level, and owning end-to-end vulnerability remediation cycles in containerised environments.
What You'll Do
1. Security Operations
The engineer owns the full lifecycle of security detection and response inside the SOC, from signal design through to automated containment. This is the primary domain of the role.
Alert design and coverage
- Design and maintain SIEM detection rules covering cloud, container, identity, and application layers, using both signature-based and behavioural logic
- Map detection coverage against the MITRE ATT&CK framework and identify gaps relevant to the organisation's AWS and EKS attack surface
- Integrate threat intelligence feeds to refresh rule logic for emerging threats and TTPs
- Maintain a detection backlog, prioritised by risk, with defined review cadences
- Daily SIEM alert triage following defined response timing standard
- Classify, investigate, and resolve security signals;
- Reduce false-positive rates through structured tuning cycles, with documented rationale for rule changes
- Maintain triage runbooks for key production detection rules
- Build and maintain SOAR playbooks for common alert types including IAM anomalies, misconfiguration alerts, exposed secrets, and container runtime events
- Automate enrichment steps (asset lookup, threat intel correlation, ownership resolution) to reduce analyst time-to-context
- Document automation logic and maintain version control for all playbooks
- Measure and report automation coverage rate as a standing KRI
Cloud posture management is the infrastructure-facing domain of the role, covering vulnerability management, identity governance, and configuration and change control. AWS EKS and Serverless resources are the primary environments.
Vulnerability management
- Own the end-to-end vulnerability triage process for cloud and container environments, prioritising findings by business impact using CVSS scoring, asset criticality, and exploitability context
- Manage EKS-specific vulnerability coverage: base image currency, workload scanning results, pod security standards compliance, and node group patching cadence
- Coordinate remediation with engineering teams by opening well-scoped tickets, tracking progress, and escalating SLA breaches
- Maintain MTTR and SLA compliance data by severity tier
- Oversee CSPM posture score targets; triage new Critical findings within defined SLA windows
- Review and approve IAM policy changes, enforcing least-privilege and flagging over-permissioned roles or service accounts
- Execute scheduled IAM hygiene reviews: unused credentials, stale access keys, overly broad policies, and cross-account trust boundaries
- Govern workload identity configurations in EKS, ensuring service accounts carry only the permissions required
- Support the secrets rotation program and enforce zero hardcoded credentials across the estate
- Review and approve cloud network security changes: security group modifications, network ACL changes, and routing updates
- Own container image security: base image update cadence, scanning results review, and image ownership classification
- Investigate and remediate misconfiguration alerts surfaced by CSPM tooling within defined SLA windows
- Maintain a configuration baseline for critical cloud resources and flag drift
3. Posture Tracking and Reporting
The engineer is the primary data owner for security posture metrics across both SOC and cloud domains. Reporting outputs feed executive dashboards, GRC compliance evidence, and quarterly risk reviews.
KRI data collection
- Collect and maintain Key Risk Indicator data across all three KRA domains on defined cadences
- SOC KRIs: MTTA (Mean Time to Acknowledge), MTTR, false-positive rate, automation coverage rate, detection coverage score
- VM KRIs: Critical/High finding counts, SLA compliance rate by severity, MTTR by tier, overdue remediation count
- Posture KRIs: CSPM score, under-protected asset count, misconfiguration closure rate, IAM hygiene score, log source coverage
- Execute infrastructure security control checks on weekly (CSPM critical findings), monthly (IAM hygiene, secrets rotation status), and quarterly (posture benchmark, detection coverage review) cadences
- Produce structured findings reports for each review cycle, flagging control failures for escalation
- Provide SOC and cloud posture metrics, including trends, at the required reporting cycles
- Support external audit and due diligence processes by providing evidence artefacts
4. Others
- Co-own the shared vulnerability backlog (infrastructure side) with the Application Security team, ensuring consistent prioritisation methodology across domains
- Serve as the infrastructure and identity SME for the AppSec team during application security assessments and architecture reviews
- Own infrastructure containment during incidents that span application and infrastructure layers, working alongside AppSec for root cause analysis
- Provide infrastructure, identity, and network security review for new third-party integrations prior to deployment
- Collaborate with the Security GRC function on control evidence and compliance mapping, particularly for SOC 2, ISO 27001, and GDPR requirements
What You'll Bring
- Fluency in English, both written and verbal
- Ability to collaborate with cross-functional teams and across different time zones
- 3 to 5 years of experience in security operations, cloud security, or infrastructure security engineering
- Hands-on AWS security experience: IAM policy design, virtual network architecture, cloud-native security services, CloudTrail, GuardDuty
- Kubernetes and EKS security experience: pod security standards, network policy enforcement, workload identity, image scanning
- SIEM operations: alert triage, detection rule authoring (signature-based and behavioural), log analysis and correlation
- Vulnerability management: CSPM tooling, risk-based prioritisation, CVSS scoring, SLA framework operation
- IaC security: ability to read and review Terraform or CloudFormation for misconfigurations
- Incident response: investigation, containment, and post-incident reporting
- Experience in a regulated environment (FinTech, payments, banking, or crypto preferred)
- Ability to author and tune detection rules without relying on vendor-supplied defaults
- Structured written communication for triage reports, post-incident write-ups, and stakeholder metrics
- Ability to coordinate remediation across engineering teams without direct authority
- Comfort operating in a lean team where domain boundaries are broader than in large enterprise security functions
- Professional certifications: AWS Security Specialty (highly valued)
- Experience with CSPM and SIEM platforms: Datadog, Wiz, Orca Security
- Experience with secrets management platforms: AWS Secrets Manager
- Familiarity with compliance frameworks: SOC 2, ISO 27001, GDPR, DORA
- Scripting ability in Python or Bash for detection-as-code and operational automation
- Experience with SOAR or workflow automation platforms
- Understanding of cryptocurrency or blockchain security considerations
- Experience in a startup or scale-up environment
- AI tooling familiarity and interest in applying AI to operational workflows
What We Offer
- Compensation & Benefits: We offer competitive compensation and meaningful health coverage, and all full-time employees are participants in our stock option plan.
- Learning & Development: Access to resources, support, and autonomy to grow professionally.
- Remote-First Flexibility: We embrace a fully remote work environment.
- Regulated, multi-geography environment with real-world impact on financial inclusion
- Mental Health Support Services: Your mental well-being matters to us.
- Ownership of the SOC and cloud security posture function from day one, in a high-growth FinTech environment
- Broad domain exposure: detection engineering, cloud security, container security, incident response, and compliance
- Collaborative team culture with a mature AppSec function and strong leadership support
Ready to Join Us?
Are you up for the challenge? Apply today and be part of shaping the future of FinTech. Let's innovate, disrupt, and lead together!
$145k - $175k
Job DescriptionWe are seeking an experienced Security Operations Engineer to help advance the next generation of security capabilities across our enterprise. This role is a technical leader responsible for designing, implementing, and continuously improving enterprise...SuggestedTemporary workWork at officeRemote work- ...change. Constantly grow as you work hard for a mission that matters at a company where you matter.Your Impact As a Senior Security Operations Engineer II, you will play a key role in building secure, reliable, and developer-friendly infrastructure that enables teams to...SuggestedWork at officeRemote work
$192k - $240k
...founders and finance teams to accelerate operations, gain real-time visibility, and control... ...support you need to grow your career.Engineering at BrexEngineering at Brex is about building... .... Our teams span Software, Data, Security, and IT, and operate with high autonomy...SuggestedWork at officeRemote workWork from home- ...believe that we provide a great place to come to work each day to pursue your passions.THE CHALLENGEWe are looking for a Security Operations Engineer to support, maintain, and contribute to our Security Orchestration, Automation, and Response (SOAR) platform. In this...SuggestedCasual workFlexible hours
- Who are we?Cohere is the leading security-first enterprise AI company. We build cutting-edge... .... Cohere is a team of researchers, engineers, designers, and more, who are all passionate... ...and Paris. Join us!As a Senior Security Operations Engineer you will:Serve as trusted...SuggestedFull timeWork at officeLocal areaRemote workHome officeFlexible hours
- ...monitoring and analyzing our organization's security infrastructure, detecting and... ...internal technology teams-including Cloud Engineering, Network Security, IAM, DevOps, and Governance... ...the continuous maturation of the SOC's operational processes. Participate in tabletop...Full timeWork at officeRemote workFlexible hours
- ...Security Operations Engineer II It's exciting to find yourself standing in a pivotal moment in time. It's even more exciting to be out front leading it. At QTS, our world-class data centers are among the most highly trusted in the industry, positioning us at the forefront...For contractorsRemote workFlexible hours
- ...Senior Security Operations Engineer At MNTN, we put our people first, full stop. This allows our company culture to be defined by our team members and their shared values, like trust, ambition, quality, radical honesty, and compassionate leadership. It's why we all...Live inRemote work
$102.1k - $202.2k
...Individual ContributorTravel: Less than 25%Profession: Security EngineeringDiscipline: Security Operations EngineeringCompany: MicrosoftOverviewIn alignment... ...every day and we need you as a Security Operations Engineer -Cloud SecurityMicrosoft’s Cloud Operations & Innovation...Ongoing contractWork at officeLocal areaWork from homeWorldwideFlexible hours3 days per week$147.5k - $211k
Location Designation: Hybrid - 3 days per week The AI / ML Security Operations Engineer is a hands-on senior engineering role embedded within the Application Security organization, responsible for securing New York Life's machine learning and AI pipelines as they evolve...Local area3 days per week$91k - $120k
...thrive, make a difference and be part of a culture where individuality is noticed and valued every day.Cyber Operations Engineer IIIJob Summary:We are seeking a Security Engineer with expertise in security automation, integration, and engineering practices to strengthen our...Full timeRemote workWork from homeFlexible hours$160k - $200k
...missions in every domain. Umbra’s ecosystem operates through three business units: Remote... ...talented Senior Cyber Threat Operations Engineer to become a key player in our vibrant team... ...with crafting and executing robust security strategies, performing in-depth threat assessments...Permanent employmentFull timeWork at officeLocal areaRemote workWorldwide$190k - $282k
...Production Engineer, Security Engineering Join to apply for the Production Engineer, Security Engineering role at CoreWeave . CoreWeave is... ...solutions for accelerated computing. Since 2017, CoreWeave has operated a growing footprint of data centers across the US and Europe...Casual workWork at officeRemote workFlexible hours- ...Secur-Serv is a leading managed services provider of IT, print, and hardware services... ...POSITION SUMMARY The Security Automation Engineer will work with customer(s) supporting... ...and completely adopt our Security Operating Platform, leaving them more secure. Develop...Work at officeRemote workWork from home
- We are seeking a Senior Security Automation Engineer to design, build, and scale enterprise-grade security automation that reduces manual effort, suppresses operational noise, and accelerates cyber defense outcomes. This role focuses on hands-on automation engineering...Temporary workRemote work
$120k - $160k
Role Description We're looking for a Senior Agentic Security Automation Engineer who thrives on technical challenges, enjoys building things from scratch, and has an insatiable curiosity for how software works, how it breaks, and how it can be analyzed autonomously....Full timeRemote workHome officeFlexible hours$130k - $155k
Role Description This position is responsible for analysis of efficiency opportunities and automation of processes in Security Operations. The candidate should be able to review operational processes and determine areas where automation can assist and to develop proof of...Full timeImmediate startFlexible hours- ...authority on architecture decisions, integration patterns, and engineering best practices within the ORCA program. This role is 100%... ...DevOps, or automation engineering, with at least 2 years in a security or infrastructure domain ~Demonstrated experience designing...Hourly payFull timeRemote work
- ...belonging through our games, their communities, and how we operate and treat each other. Through our game communities, we... ...About the Role Fortis Games is looking for a Senior Security Operations Engineer, Detection and Response to help build and mature our security...Full timeRemote workWeekend work
- ...Upstart is seeking a SecOps Engineer to design automated response mechanisms, triage critical alerts, hunt for threats, and help build our security data lake. You’ll be on the front lines of incident response, protecting our core product platforms and enterprise infrastructure...Remote work
- ...The Canonical Security Operations team is hiring for a Senior or Staff engineer. The Security Operations team is responsible for designing, building, and operating a world-class Security Operations Center, and the successful candidate will provide leadership, mentorship...Remote jobFull timeLocal areaWorldwide
$138.38k - $195.47k
...The Senior Security Operations Engineer is responsible for designing, implementing, and improving Data Loss Prevention (DLP) protections across Included Health's corporate and cloud environments. You will lead hands‑on deployment and tuning of DLP controls, including...Work at officeLocal areaRemote workWork from homeHome office- ...drills that simulate real attack scenarios, identifying potential security risks in enterprise networks, applications, cloud environments... ...XFN collaboration Collaborate with the blue team, security operation, infrastructure, R & D, algorithm, data, and business teams to...Full time
- ...Sustainability Lighthouses for breakthroughs in efficient operations. With our global reach, we ensure the global... ...ID device migration and providing Entra ID engineering support across the organization. The Staff Security Operations Engineer serves as a key technical...Temporary workWork at officeRemote workHome officeFlexible hoursShift work
- ...software architectures that support the bank’s information security operations functions. This role performs feedback and recommendation in... .... The position serves as a technical resource for security engineering initiatives, applying advanced knowledge to evaluate, build...Remote work
- Position: Senior Security Engineer - PKI & Detection, Aircraft SecurityLocation: Fort Worth Texas (Hybrid - onsite Tuesday through Thursday;... ...Infrastructure (PKI). This role will independently design and operate security solutions, investigate security events, develop...Full timeRemote workMonday to Friday
$100k - $140k
...solutions deliver value across enterprise security performance, digital supply chains,... ...a skilled and passionate Cybersecurity Engineer to strengthen and scale our security capabilities... ...handling and response, including SOC operations and DFIR.Enforce least privilege access...Full timeRemote workFlexible hours$165k - $242k
...more at .What You’ll Do:The Enterprise Security team at CoreWeave is responsible for securing... ....About the Role:As a Senior Security Engineer, Enterprise Security, you’ll design and... ...and access controlsDesign, implement, and operate workforce identity solutions (e.g., Okta...Permanent employmentFull timeTemporary workFor contractorsCasual workWork at officeRemote workFlexible hours$178.4k - $226.7k
AHAS reduces the risk of human and operator access to AWS production systems and customer environments. As the Senior Security Engineer embedded with an AHAS software development team, you own the security design decisions for the operator-access tooling this team builds...InternshipRemote workFlexible hours$107.93k - $188.9k
...Cyber Defense and Resilience offering is seeking a SIEM Engineer to support security monitoring, detection engineering, and incident analysis... ...triage, and response activitiesDocument detection logic, operational procedures, and monitoring requirements to support consistent...Remote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Operations Engineer [Remote]. Be the first to apply!
- offensive security engineer Remote
- staff security engineer Remote
- cloud security engineer Remote
- IT security engineer Remote
- information technology security engineer Remote
- security engineer Remote
- senior application security engineer Remote
- security operations engineer Remote
- product security engineer Remote
- sr information security engineer Remote




